Sovereign AI deployment in the UK and EU: where can the model run, and what proves it?
It can run in three places: a managed model service in an EU region of your own cloud tenant, open weights on EU-resident capacity, or open weights on your own premises with no outside connection. What shows it is the contract’s stated locations and the deployment’s configuration; the kit adds a list of the providers the system may call.
David McMillan, Governed AI Deployment. Checked against the sources on .
§01GDPR Art. 44 to 49, DORA Art. 28
Three places the model can run
- S1In-tenant managed
- A managed model service (Azure OpenAI, or Anthropic on Bedrock or Vertex) in an EU region of your own cloud tenant, under your identity and network controls, with no training on your data. The default for most UK and EU firms.
- S2EU-hosted open weights
- An open-weight model your model-risk review has approved, on EU-resident GPU capacity you rent or own. For a policy that rules out US-parented API providers, or where a DORA assessment of ICT concentration risk argues against one.
- S3Air-gapped on premises
- Open weights on hardware inside your building, with no egress at all. For the systems a CISO says must never leave it.
§02GDPR Art. 44 to 49, DORA Art. 30
What the law asks about location
Personal data sent outside the European Economic Area can go only on the conditions GDPR sets for transfers (GDPR Art. 44 to 49). An EU bank’s contract must state where the service runs and data is processed. In the DORA regulation’s words:
the locations, namely the regions or countries, where the contracted or subcontracted functions and ICT services are to be provided and where data is to be processed, including the storage location, and the requirement for the ICT third-party service provider to notify the financial entity in advance if it envisages changing such locations;
DORA Art. 30
§03
Azure OpenAI in an EU region
Microsoft’s documentation sets out where prompts and responses are processed, by deployment type. In its words:
Prompts and responses are processed within the customer-specified geography (unless you are using a Global or DataZone deployment type), but may be processed between regions within the geography for operational purposes (including performance and capacity management).
For any deployment type labeled 'Global,' prompts and responses may be processed in any geography where the relevant model sold by Azure is deployed (learn more about region availability of models).
If you create a DataZone deployment in a Foundry resource located in a European Union Member Nation, prompts and responses may be processed in that or any other European Union Member Nation.
Microsoft
So the deployment type matters as much as the region: a Global deployment can process data outside the EU. Data stored at rest stays in the geography the customer designates, by the same documentation.
§04GDPR Art. 44 to 49, DORA Art. 30
What proves it
Three records together: the contract or service terms stating the locations; the deployment’s configuration, showing the region and the deployment type; and, in the kit, the list of model providers the system may call, with a lint rule and a test that refuse a call to any of them from code outside one zone. Neither check catches every way of writing a call, and the kit records the ones still open. Whether that is enough for a given data flow is for the firm and its counsel.
§05
Sources
- Regulation (EU) 2016/679, the GDPR, on EUR-Lex
https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
- Regulation (EU) 2022/2554, the DORA regulation, on EUR-Lex
https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng
- Microsoft, Data, privacy, and security for Azure Direct Models in Microsoft Foundry (learn.microsoft.com)
https://learn.microsoft.com/en-us/azure/ai-foundry/responsible-ai/openai/data-privacy
§06
Book a scoping call
Thirty minutes on one system: what it does, who is asking about it, and which engagement fits. Nothing to prepare. For firms in the UK and Europe.